The convergence of Software-Defined Access (SD-Access) with Cyber-Physical Systems (CPS) and Industrial IoT (IIoT) introduces a class of latent, cross-layer security risks that are structurally invisible to conventional assessment tools. Three orthogonal sources characterise this threat surface: the divergence between physical underlay connectivity and logical overlay reachability inherent in the LISP/VxLAN encapsulation model; the encapsulation boundary opacity that renders inner security context—Scalable Group Tags, Virtual Network membership—invisible to underlay switching devices; and the implicit fabric-wide trust relationships embedded in the centralised LISP Control Plane. We present a Security Twin methodology that formalises the SD-Access architecture as a dual-layer directed multigraph GS = ⟨NS , Ephy ∪Elog⟩, where physical and logical edges are governed by distinct generation rules capturing the two-tier segmentation hierarchy and its failure modes. A stochastic Attacker Twin model employs Monte Carlo simulation (N = 100,000 iterations) to generate probabilistic Intrusion Graphs and five quantitative risk metrics—Compromise Probability Pc, Blast Radius BR, Critical Path Distance dc, Segmentation Efficacy Ratio Ψ, and Control Plane Exposure Index ECP—that provide a reproducible, architecture-agnostic basis for comparative segmentation analysis. Experimental evaluation over a 28-node enterprise branch topology demonstrates that SD-Access reduces database server compromise probability by 78.3% relative to a legacy VLAN baseline. Critically, the Underlay Breakout vector—exploitation of unprotected management interfaces on IS-IS underlay switches to bypass VRF isolation—is identified as the dominant residual risk contributor; targeted management plane hardening delivers a further 46% reduction through configuration changes alone. A federated extension with formal (εDP=1.0, δDP=10−5)-differential privacy guarantees enables multi-domain Security Twin collaboration without centralising sensitive topology or policy data.
Model-Driven Security Analysis of SD-Access Fabrics Using Digital Twins: A Probabilistic Framework in Software-Defined Campus and Cyber-Physical Networks
Vincenzo Sammartino
Primo
;
2026-01-01
Abstract
The convergence of Software-Defined Access (SD-Access) with Cyber-Physical Systems (CPS) and Industrial IoT (IIoT) introduces a class of latent, cross-layer security risks that are structurally invisible to conventional assessment tools. Three orthogonal sources characterise this threat surface: the divergence between physical underlay connectivity and logical overlay reachability inherent in the LISP/VxLAN encapsulation model; the encapsulation boundary opacity that renders inner security context—Scalable Group Tags, Virtual Network membership—invisible to underlay switching devices; and the implicit fabric-wide trust relationships embedded in the centralised LISP Control Plane. We present a Security Twin methodology that formalises the SD-Access architecture as a dual-layer directed multigraph GS = ⟨NS , Ephy ∪Elog⟩, where physical and logical edges are governed by distinct generation rules capturing the two-tier segmentation hierarchy and its failure modes. A stochastic Attacker Twin model employs Monte Carlo simulation (N = 100,000 iterations) to generate probabilistic Intrusion Graphs and five quantitative risk metrics—Compromise Probability Pc, Blast Radius BR, Critical Path Distance dc, Segmentation Efficacy Ratio Ψ, and Control Plane Exposure Index ECP—that provide a reproducible, architecture-agnostic basis for comparative segmentation analysis. Experimental evaluation over a 28-node enterprise branch topology demonstrates that SD-Access reduces database server compromise probability by 78.3% relative to a legacy VLAN baseline. Critically, the Underlay Breakout vector—exploitation of unprotected management interfaces on IS-IS underlay switches to bypass VRF isolation—is identified as the dominant residual risk contributor; targeted management plane hardening delivers a further 46% reduction through configuration changes alone. A federated extension with formal (εDP=1.0, δDP=10−5)-differential privacy guarantees enables multi-domain Security Twin collaboration without centralising sensitive topology or policy data.I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.


